Jobs and Careers
BR

Sr. Analyst Information Security

Bread Financial
P1 - Easton Campus Building A, United States, United Statesfull_timeVerifiedPosted 30 Jan 2025
💰 $221,800/yr($97,900/yr$221,800/yr)

About the role

Every career journey is personal. That's why we empower you with the tools and support to create your own success story.

Be challenged. Be heard. Be valued. Be you ... be here.

Job Summary

The Sr. Analyst, Info Sec is responsible for overseeing and managing multiple risks, audits, and controls within the Information Technology Domain. This person is expected to be a strategic partner to control owners, second line of defense, and privacy leaders. The position reports to the Manager, Information Security and works closely with other Information Security Domain Champions.


 

Essential Job Functions 

  • Audit coordination and evidence collection: Facilitate the collection of evidence for various audit and control activities such as PCI-DSS, NIST CSF, GLBA 501-B, Sarbanes Oxley, etc Review evidence for appropriateness and adequacy. Track and report on all evidence requests to ensure request deadlines are met.   Coordinate and facilitate audit and/or control interviews as well as necessary follow up meetings between control owners and internal/external auditors. Publish meeting minutes and track action items to completion.  Utilizes planning and organization tools to develop project/action plans.  Meets deliverable deadlines as directed. 
  • Payment Card Industry (PCI) Annual Audit: Possess in-depth knowledge of the PCI-DSS and obtain PCI-DSS Internal Security Assessor Certification (ISA) within 6 months of starting position.  Test PCI controls and work with control owners to resolve control design or operating effectiveness issues ahead of and during annual Company PCI Audit. Partner with external Qualified Security Assessor (QSA) to reduce scope and control testing where possible.  Use knowledge of General IT Computing Controls and Cyber Security Tools to create PCI Compensating Control Matrices when required. 
  • Control Coaching, Consulting, and Collaboration: Partner with IT Control Owners to identify, resolve, mitigate, or compensate for control failures identified through risk assessments, internal/external audits, or cyber security tools and processes.  Develop proactive risk and control assessment strategies to stay ahead of emerging risks and regulatory requirements. 

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Bread Financial

View company profile →